Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Outlaw Chemist Teaching People How to Make Drugs From Scratch

    August 11, 2026

    Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

    August 11, 2026

    ‘Disappointing’ — Crypto Advocates React to Delay in CLARITY Vote

    August 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Outlaw Chemist Teaching People How to Make Drugs From Scratch
    • Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
    • ‘Disappointing’ — Crypto Advocates React to Delay in CLARITY Vote
    • England set to eliminate hepatitis C
    • Dragon roars with record power in Faroe Islands: Minesto hits new tidal energy output milestone
    • Live: Russian missiles strike Kyiv, triggering fires in city centre
    • Trump media group racks up losses and pushes into nuclear fusion
    • The Best Portable Solar Panels: My Take After Years of Testing
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Multistate Water System Attacks Widen, Iran Suspected

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 10, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cyberattacks against water and wastewater systems reportedly have reached at least a dozen states, with threat actors exploiting low-complexity attacks against industrial controllers. The intrusions, possibly linked to the Iranian government, prove the US’s water infrastructure remains dangerously exposed.

    In recent weeks, water and wastewater organizations associated with a number of different US states have disclosed cyberattacks against their systems. Minnesota was the first to confirm such attacks late last month, saying that cyberattackers targeted operational technology (OT) systems for more than 30 water systems. Around the same time on July 30, the Cybersecurity and Infrastructure Security Agency (CISA) updated an earlier advisory warning of “a significant increase in cyber-threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector.”

    Related:Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks

    The US cyber agency said threat actors were modifying PLC passwords to lock out operators and also disconnecting PLCs by changing their IP addresses. “CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other OT from the Internet as soon as possible,” CISA said at the time.

    This CISA advisory followed the FBI updating an April warning on July 22 that Iranian threat actors are targeting PLCs in critical infrastructure manufactured by Rockwell Automation/Allen Bradley, Schneider Electric, Siemens, and possibly other vendors.

    It’s not just Minnesota. Relevant municipal and local water officials from Georgia, Michigan, and South Dakota have also suffered attacks that appear to be connected with this wider campaign. And in recent days, Alabama and New Jersey communities have similarly confirmed attacks.

    Modernize to Stem the Flow of Water Sector Disruptions

    So far there’s been no disruption to the water supply, and these PLC attacks appear to be intended to stoke fear rather than carry out permanent damage or extortion, at least to public knowledge.

    That’s not to say there’s not disruption happening. Some of the attacks to date, such as the ones in Minnesota, involved locking local operators out of PLCs while disrupting visibility and control functions, forcing operators to use manual workarounds. South Dakota and Michigan-targeted attacks appeared to be consistent with this. The most severe activity known to date involved Georgia, where cyber activity against Clayton County reportedly caused a water pressure drop and forced the agency to issue a boil water advisory.

    Related:Iran, Russia, China Target Water Systems for Sabotage

    John Gallagher, vice president at OT and IoT security firm Viakoo, says industrial controllers like PLCs were historically engineered for physical isolation and reliability rather than Internet exposure, meaning that many lack basic secure-by-design capabilities like multifactor authentication (MFA) or encrypted communication.

    “Like many OT and Internet of Things (IoT) systems, they may have built-in networking that is turned on by default unless it is disabled during installation,” he tells Dark Reading. “This is compounded by maintenance which often is done by non-IT staff; field technicians and third-party integrators frequently install cellular modems, satellite links, or direct port forwards to allow remote troubleshooting without notifying central IT/OT teams.”

    Markus Mueller, field CISO at Nozomi Networks, similarly says that PLCs are common targets because of the reality behind how the water and wastewater industry operates.

    “There are roughly 170,000 drinking water and wastewater systems, and most are small, decentralized, and running OT that was installed by a third party,” he explains. “Cyber awareness and capabilities are limited at these utilities. There is an operational need for these devices to be connected, but there’s also a lack of funding, mandate, or awareness to keep them secure. It is unfortunate, as there are plenty of good people in the water industry who work hard to deliver clear, reliable water, but they are not cyber people. And even if they are aware of the issue, they often can’t get the budget or resources to set up these systems properly.”

    Related:Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control

    Is Iran Turning on the Utility Cyberattack Taps?

    While there has been no definitive attribution as to who’s behind the offensive, one possible culprit is the pro-Iran CyberAv3ngers hacktivist group, which has hit US water infrastructure before, according to a CISA alert from 2023 and 2024.

    Researchers have previously called the group opportunistic and propagandistic in nature, leaning on lower stakes attacks to stoke public fear and gain media attention. Attacks like this are closer to hacktivism in nature — as if the threat actor is trying to say, “We can get to you.”

    That said, several cybersecurity firms and researchers have noted similarities between the recent PLC-targeting campaign and previous operations attributed to the Iranian Revolutionary Guard Corps (IRGC) and/or the IRGC-linked CyberAv3ngers group, though federal authorities have not publicly attributed the latest multistate water-sector intrusions to either.

    Mueller tells Dark Reading that a lack of sophistication in tradecraft does not necessarily mean the adversary is not capable of more.

    “Adversaries will deploy the tactics, techniques, and procedures (TTPs) that are needed to meet the objective they have,” he says. “The scale and coordination required for this campaign point to a well-organized adversary that likely is technically capable of more. Based on this, I assess with moderate confidence that the adversary is focused on a widespread disruption and causing pain to operators and responders. In a lot of ways, this aligns with the hacktivist playbook we have seen, but the missing component is the claims of responsibility and, frankly, the marketing from the adversary.”

    attacks Iran Multistate Suspected System water Widen
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

    China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

    BdThemes plugins supply-chain hack creates rogue WordPress admins

    Sherlock Holmes was the “OG” Social Engineer

    Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

    Outdated Cybercrime Laws Put Security Researchers at Risk

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Outlaw Chemist Teaching People How to Make Drugs From Scratch

    August 11, 2026

    Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

    August 11, 2026

    ‘Disappointing’ — Crypto Advocates React to Delay in CLARITY Vote

    August 11, 2026

    England set to eliminate hepatitis C

    August 11, 2026
    Latest Posts

    Harbour Energy’s US arm advances repair plan after riser leak at Gulf of America oil & gas asset

    July 24, 2026

    Beavers restored a volcano-scarred river. Now it’s at risk again

    July 24, 2026

    China’s Tianwen-1 captures interstellar comet 3I/ATLAS near Mars

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Outlaw Chemist Teaching People How to Make Drugs From Scratch

    August 11, 2026

    Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

    August 11, 2026

    ‘Disappointing’ — Crypto Advocates React to Delay in CLARITY Vote

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.